Registry:
IoOpenDeviceRegistryKey
IoOpenDeviceInterfaceRegistryKey
ZwOpenKey
ZwClose
ZwQueryValueKey
ZwSetValueKey
RtlDeleteRegistryValue
…
File:
Must running at PASSIVE_LEVEL
ZwCreateFile
ZwClose
ZwReadFile
ZwWriteFile

